CVE-2009-0260: XSS
Multiple cross-site scripting (XSS) vulnerabilities in action/AttachFile.py in MoinMoin before 1.8.1 allow remote attackers to inject arbitrary web script or HTML via an AttachFile action to the WikiSandBox component with (1) the rename parameter or (2) the drawing parameter (aka the basename variable).
Other sources
Multiple cross-site scripting (XSS) vulnerabilities in action/AttachFile.py in MoinMoin before 1.8.1 allow remote attackers to inject arbitrary web script or HTML via an AttachFile action to the WikiSandBox component with (1) the rename parameter or (2) the drawing parameter (aka the basename variable).
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
debian/mointo a version that resolves this vulnerability.Fixed in 1.9.9-1+deb10u1 - Upgrade
Upgrade
pip/mointo a version that resolves this vulnerability.Fixed in 1.8.1
Event History
Frequently Asked Questions
What is the severity of CVE-2009-0260?
CVE-2009-0260 has been classified as a medium severity vulnerability due to its cross-site scripting (XSS) potential.
How do I fix CVE-2009-0260?
To fix CVE-2009-0260, upgrade to MoinMoin version 1.8.1 or later.
Which versions of MoinMoin are affected by CVE-2009-0260?
CVE-2009-0260 affects MoinMoin versions prior to 1.8.1, including all versions from 0.1 to 1.8.0.
Can CVE-2009-0260 be exploited remotely?
Yes, CVE-2009-0260 can be exploited remotely, allowing attackers to inject arbitrary scripts through affected actions.
What components of MoinMoin does CVE-2009-0260 affect?
CVE-2009-0260 affects the 'AttachFile' action within the WikiSandBox component of MoinMoin.